Technology & Security FAQ
Key Terms Used in This FAQ
- ePHI (Electronic Protected Health Information): Any health information that is created, received, maintained, or transmitted in electronic form and is individually identifiable. Protected under the HIPAA Security Rule.
- BAA (Business Associate Agreement): A contract required under HIPAA between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on the entity's behalf.
- Technical Safeguards: The technology and related policies that protect ePHI and control access to it, as defined in 45 CFR Section 164.312.
- Encryption at Rest: Protecting stored data by converting it into an unreadable format that requires a decryption key to access.
- Encryption in Transit: Protecting data as it moves between systems (such as over email or the internet) using protocols like TLS.
- Access Control: The ability to restrict who can view or use ePHI, including unique user identification, emergency access procedures, automatic logoff, and encryption mechanisms.
Cloud Storage and HIPAA
Yes, cloud storage is permitted under HIPAA provided the cloud service provider signs a BAA and implements safeguards required under 45 CFR Section 164.312. These safeguards include access controls, audit controls, integrity controls, and transmission security.
The cloud provider must ensure that ePHI is encrypted both at rest and in transit, and that access is limited to authorized users. Your Business Associate Agreement must specifically cover the cloud services being used.
Email Compliance Under HIPAA
A free Gmail account does not meet HIPAA requirements. Google does not offer a BAA for free Gmail accounts, and the free tier lacks the administrative controls needed for HIPAA compliance.
Paid Google Workspace plans (Business Starter, Business Standard, Business Plus, and Enterprise) can support HIPAA compliance when configured correctly and covered by a signed BAA with Google. The BAA must be accepted through the Google Admin console before any ePHI is transmitted or stored. See our BAA FAQ for details on vendor BAA requirements.
Microsoft Outlook can meet HIPAA requirements when used as part of a Microsoft 365 plan that includes a BAA. Microsoft offers a BAA for its enterprise and business plans (Microsoft 365 Business Premium, E3, E5, and equivalent tiers).
The free Outlook.com accounts do not qualify for HIPAA compliance, as Microsoft does not offer a BAA for consumer-tier services. Organizations must ensure that encryption for data at rest and in transit is enabled, and that the Business Associate Agreement with Microsoft covers the specific configurations used for ePHI.
PHI can be sent by email when appropriate safeguards are in place. At minimum, email containing ePHI must use encryption in transit (TLS) and should use encryption at rest. Your HIPAA policies should document approved email encryption methods and staff should receive training on secure communication procedures.
Messaging and PHI
Standard SMS text messaging is not considered secure for PHI transmission. SMS messages are not encrypted in transit, can be stored in plaintext on carrier servers, and cannot be remotely wiped from a recipient's device.
HIPAA-compliant alternatives include secure messaging platforms with encryption per 45 CFR Section 164.312(e), which requires covered entities to implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic communications networks. Your HIPAA policies should define which communication channels are approved for PHI.
Remote Work and Device Security
Yes. Remote work is permitted under HIPAA as long as the organization maintains administrative, physical, and technical safeguards. The regulatory basis for remote work requirements spans two sections:
- 45 CFR Section 164.310 (Physical Safeguards) - requires policies governing workstation use and security, including remote workstations
- 45 CFR Section 164.312 (Technical Safeguards) - requires access controls, audit controls, integrity controls, and transmission security for all systems accessing ePHI, regardless of location
Remote work policies should be documented in your HIPAA policies and all remote staff must complete HIPAA training that addresses remote work procedures.
In some cases, yes. Before allowing home devices to access ePHI, organizations must assess encryption, access controls, physical security, remote wipe capability, and staff policies. A Security Risk Assessment helps identify these risks and determine what controls are needed for home device access.
Essential Safeguards
Not using encryption on systems, devices, and data where it is required. Gaps in encryption are one of the most common findings in a HIPAA Gap Analysis. The HIPAA Security Rule identifies encryption as an addressable implementation specification, meaning organizations must either implement it or document why an equivalent alternative is appropriate.
Encryption remains the most frequently overlooked safeguard in healthcare. Regular workforce training should reinforce encryption requirements, and a gap analysis can identify where encryption is missing across your environment.
Tools that enhance visibility, security monitoring, and alerting. Even basic monitoring solutions that track irregular activity can significantly improve compliance posture. A Security Risk Assessment helps identify which technology investments will have the greatest impact on protecting ePHI.
One Guy Consulting helps practices review their tech safeguards as part of the Security Risk Assessment process. Our HIPAA Gap Analysis finds gaps in your tech, admin, and physical safeguards.
Need Help Evaluating Your Technology Safeguards?
Book a free 30-minute intro call. We will review your tech setup, find security gaps, and explain what safeguards you need.
Book Your Free Intro CallMore HIPAA FAQ Resources
- HIPAA compliance FAQ covering basics, risk assessments, training, and policies
- HIPAA audit readiness frequently asked questions
- Business Associate Agreement frequently asked questions
- Security Risk Assessment service details
- Real-world HIPAA compliance case studies
- Full pricing comparison with plan details